Candidate: CVE-2016-2038 PublicDate: 2016-02-20 01:59:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-2038 https://www.phpmyadmin.net/security/PMASA-2016-1/ Description: phpMyAdmin 4.0.x before 4.0.10.13, 4.4.x before 4.4.15.3, and 4.5.x before 4.5.4 allows remote attackers to obtain sensitive information via a crafted request, which reveals the full path in an error message. Ubuntu-Description: Notes: Bugs: Priority: low Discovered-by: Emanuel Bronshtein Assigned-to: CVSS: nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N [5.3 MEDIUM] Patches_phpmyadmin: upstream: https://github.com/phpmyadmin/phpmyadmin/commit/ac81596bfcf0b3cae9f6bc821efa4aa1c7f0c81d (4.0) upstream: https://github.com/phpmyadmin/phpmyadmin/commit/8023340a259ecae6a3bd9268f4e39d097bdf0146 (4.0) upstream: https://github.com/phpmyadmin/phpmyadmin/commit/215f4a8ebe717ba646be00fca8519cf768a902f5 (4.0) upstream: https://github.com/phpmyadmin/phpmyadmin/commit/7056ca9458d26b24a6b1d9255073237c1636ca33 (4.0) upstream: https://github.com/phpmyadmin/phpmyadmin/commit/25738352df8057b542eeac3237eb6fd1d3ba4289 (4.0) upstream: https://github.com/phpmyadmin/phpmyadmin/commit/5b79467245b6e0a476775e2958b42088794f8e02 (4.0) upstream: https://github.com/phpmyadmin/phpmyadmin/commit/b39c02b0a82b13d2198276d228051139e6b838d9 (4.4) upstream: https://github.com/phpmyadmin/phpmyadmin/commit/470cd68344e86915679356dcc2cdb88c63a1d91d (4.4) upstream: https://github.com/phpmyadmin/phpmyadmin/commit/b95360334d69b032b58cafb7d29db6670e9c7224 (4.4) upstream: https://github.com/phpmyadmin/phpmyadmin/commit/d63a8ab7e028925707902266fc989760118a4c72 (4.4) upstream: https://github.com/phpmyadmin/phpmyadmin/commit/879a14ad165b475ec58ceab33687d7cc5913a63b (4.4) upstream: https://github.com/phpmyadmin/phpmyadmin/commit/d0a9baef3728a37120d53dc0a96abf04ace139da (4.4) upstream: https://github.com/phpmyadmin/phpmyadmin/commit/5aee5035646c4fc617564cb0d3d58c0435d64d81 (4.5) upstream: https://github.com/phpmyadmin/phpmyadmin/commit/85ccdbb5b9c6c7a9830e5cb468662837a59a7aa3 (4.5) upstream: https://github.com/phpmyadmin/phpmyadmin/commit/447c88f4884fe30a25d38c331c31d820a19f8c93 (4.5) upstream: https://github.com/phpmyadmin/phpmyadmin/commit/f83b52737e321005959497d8e8f59f8aaedc9048 (4.5) upstream: https://github.com/phpmyadmin/phpmyadmin/commit/76b10187c38634a29d6780f99f6dcd796191073b (4.5) upstream: https://github.com/phpmyadmin/phpmyadmin/commit/d4b9c22c1f8465bda5b6a83dc7e2cf59c3fe44e1 (4.5) upstream_phpmyadmin: released (4:4.5.4-1) precise_phpmyadmin: ignored (reached end-of-life) precise/esm_phpmyadmin: DNE (precise was needed) trusty_phpmyadmin: ignored (out of standard support) trusty/esm_phpmyadmin: needed vivid_phpmyadmin: ignored (reached end-of-life) vivid/stable-phone-overlay_phpmyadmin: DNE vivid/ubuntu-core_phpmyadmin: DNE wily_phpmyadmin: ignored (reached end-of-life) xenial_phpmyadmin: not-affected (4:4.5.4-1) yakkety_phpmyadmin: not-affected (4:4.5.4-1) zesty_phpmyadmin: not-affected (4:4.5.4-1) artful_phpmyadmin: not-affected (4:4.5.4-1) bionic_phpmyadmin: not-affected (4:4.5.4-1) cosmic_phpmyadmin: not-affected (4:4.5.4-1) disco_phpmyadmin: not-affected (4:4.5.4-1) eoan_phpmyadmin: DNE focal_phpmyadmin: not-affected (4:4.5.4-1) groovy_phpmyadmin: not-affected (4:4.5.4-1) hirsute_phpmyadmin: not-affected (4:4.5.4-1) impish_phpmyadmin: not-affected (4:4.5.4-1) jammy_phpmyadmin: not-affected (4:4.5.4-1) devel_phpmyadmin: not-affected (4:4.5.4-1)